boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Ibm

Vendor reference — Ibm · sector: Enterprise Applications. Cumulative disclosure record across the archive.

Follow Ibm — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs10521047
KEV entries61
Rate & severity
KEV/100Med CVSSMed EPSSCHML
0.67.5.003719949334218

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▃██▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-0549
2026-0675
2026-07105
2026-08390
2026-09404
2026-1024

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2022-479869.8100.0CRITICALYES2023-02-17
CVE-2019-471610.099.7CRITICALYES2019-12-18
CVE-2020-44279.099.4CRITICALYES2020-05-07
CVE-2020-44304.399.3MEDIUMYES2020-05-07
CVE-2020-44289.199.2CRITICALYES2020-05-07
CVE-2026-91989.898.1CRITICALYES2026-07-17
CVE-2026-1377310.093.2CRITICAL—2026-06-30
CVE-2026-91039.887.8CRITICAL—2026-07-17
CVE-2026-171796.587.4MEDIUM—2026-08-14
CVE-2026-192959.987.0CRITICAL—2026-08-28
CVE-2026-855428.883.6HIGH—2026-09-25
CVE-2026-187298.877.6HIGH—2026-08-28
CVE-2026-164688.876.6HIGH—2026-09-22
CVE-2026-149597.274.3HIGH—2026-07-28
CVE-2026-168508.873.5HIGH—2026-08-19

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-936787.630.1HIGH—2026-10-07
CVE-2026-934486.549.0MEDIUM—2026-10-07
CVE-2026-936794.338.6MEDIUM—2026-10-07
CVE-2026-936777.737.8HIGH—2026-10-07
CVE-2026-976716.536.8MEDIUM—2026-10-07
CVE-2026-934437.546.1HIGH—2026-10-07
CVE-2026-936749.853.7CRITICAL—2026-10-07
CVE-2026-976738.835.8HIGH—2026-10-07
CVE-2026-934498.546.1HIGH—2026-10-07
CVE-2026-936758.850.8HIGH—2026-10-07
CVE-2026-934458.147.5HIGH—2026-10-07
CVE-2026-934477.535.1HIGH—2026-10-07
CVE-2026-889628.854.9HIGH—2026-10-07
CVE-2026-1043358.845.1HIGH—2026-10-06
CVE-2026-1013296.516.2MEDIUM—2026-10-06

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
AIX1450
PowerVM VIOS1450
Langflow OSS1411
I1410
WebSphere Application Server550
Guardium Data Protection540
Financial Transaction Manager (FTM) for RedHat OpenShift460
DataStage On Cloud Pak For Data450
Security Verify Access260
Security Verify Access Container260
Verify Identity Access260
Verify Identity Access Container260
WebSphere Application Server - Liberty260
Db2240
Db2 Mirror For I240
MQ220
App Connect Enterprise190
PowerVM Hypervisor190
Concert180
Power Systems Firmware160
Sterling File Gateway130
Sterling B2B Integrator110
Integration Bus For Z/OS100
Watsonx.data Intelligence100
Cloud Pak For Business Automation80
Common Licensing80
HTTP Server80
Cognos Analytics70
Business Automation Workflow Containers And Traditional60
MQ For HPE NonStop60
I Access Client Solutions60
ContextForge MCP Gateway50
Documentation Offline50
Netezza Software50
OPENBMC50
QRadar50
UCD - IBM DevOps Deploy50
Aspera High-Speed Transfer Endpoint40
Aspera High-Speed Transfer Server40
CICS TX Advanced40
Controller40
Engineering AI Hub40
Engineering Lifecycle Management40
Enterprise Build Of Quarkus40
UCD - IBM UrbanCode Deploy40
WebSphere Extreme Scale40
I Access Family40
Aspera Faspex 530
Data Risk Manager33
DataPower Gateway 10.5.030
DataPower Gateway 10.6.030
Datacap30
Datacap Navigator30
Db2 On Cloud Pak For Data And Db2 Warehouse On Cloud Pak For Data30
Informix Dynamic Server30
Observability With Instana (Agent)30
Operations Analytics - Log Analysis30
API Connect20
Administration Runtime Expert For I20
Aspera Desktop App20
Cloud Pak For Data20
Cloud Pak For Data System20
Cloud Pak For Data System - Cyclops20
Cognos Transformer20
DS8900F (R9.4)20
DS8A00 (R10.0 - R10.1)20
DataPower Gateway 10.6CD20
DataPower Gateway 11.0.020
Engineering Requirements Management DOORS And DOORS Web Access20
Engineering Workflow Management20
Financial Transaction Manager For SWIFT Services For Multiplatforms20
Integrated Analytics System20
Maximo Application Suite20
Planning Analytics21
PowerVM Novalink20
Qiskit SDK20
Server Firmware20
Sterling Secure Proxy20
Storage Protect Client20
Storage Scale20
Tivoli System Automation Application Manager20
Web Server Plug-ins For WebSphere Application Server And WebSphere Liberty20
Mcp-context-forge20

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-91982026-08-049.898.1CRITICAL
CVE-2022-479862023-02-219.8100.0CRITICAL
CVE-2019-47162021-11-0310.099.7CRITICAL
CVE-2020-44282021-11-039.199.2CRITICAL
CVE-2020-44272021-11-039.099.4CRITICAL
CVE-2020-44302021-11-034.399.3MEDIUM

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2020-44302022-05-031619
CVE-2020-44272022-05-031619
CVE-2020-44282022-05-031619
CVE-2019-47162022-05-031619
CVE-2022-479862023-03-141304
CVE-2026-91982026-08-0762

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.